2002-04-26 08:51:39 -04:00
|
|
|
Snort is a fairly intelligent sniffer/NIDS, with a very strong rule set.
|
2000-07-24 03:57:51 -04:00
|
|
|
|
2004-04-12 10:56:31 -04:00
|
|
|
Snort can perform protocol analysis, content searching/matching and can be used
|
|
|
|
to detect a variety of attacks and probes, such as buffer overflows, stealth
|
|
|
|
port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more.
|
2001-08-16 10:02:46 -04:00
|
|
|
|
2004-04-12 10:56:31 -04:00
|
|
|
Snort uses a flexible rules language to describe traffic that it should collect
|
|
|
|
or pass, as well as a detection engine that utilizes a modular plugin
|
|
|
|
architecture. Snort has a real-time alerting capability as well, incorporating
|
|
|
|
alerting mechanisms for syslog, a user specified file, a UNIX socket, or
|
|
|
|
WinPopup messages to Windows clients using Samba's smbclient.
|
2001-08-16 10:02:46 -04:00
|
|
|
|
|
|
|
Available flavors:
|
|
|
|
postgresql - enable postgresql database logging support
|
|
|
|
mysql - enable mysql database logging support
|
|
|
|
flexresp - enable dynamic connection killing support
|